Update: CLI version of MiniEnv is coming soon

MiniEnv is the smallest way to share a .env file.

Encrypted on your Mac with age before it goes anywhere. One list of who can read it. Free for five people.

Download free for
Apple Silicon · macOS 12 or later
Read how it works, including what we can still see →
Pro
PROJECTS
+ Add Project
Settings
orbit-api
Shared with 2 people
Show All
+ Add
Prod 4
Staging 1
+
NAME
VALUE
UPDATED
SHARED WITH 2+
N
Nadia · owner
nadia@orbit.dev
T
Theo
theo@orbit.dev
4 values in Prod
Encrypted on this Mac. The relay cannot read them.

Someone leaves.
They lose everything,
at once.

Remove a person and every value they had access to is re-encrypted on your Mac, before the change is accepted. There is no window where they can still read new values, and no background job that gets round to it later.

What it does not do, and what no tool can do, is reach backwards. Anything they already pulled, they still have. Rotate that at the source: the database, the provider. Not just here.

Read the full model, including the narrow race we have not closed yet.

We never hold
anything readable.

We didn't invent our own cryptography. MiniEnv uses age, the same standard the serious tools rely on. Values are encrypted on your machine before they leave it, so our server only ever stores ciphertext. If the whole database leaked tomorrow, an attacker would walk away with unreadable blobs.

# on your machine
STRIPE_SECRET_KEY=sk_live_51Nc…q8Xv
# what our server stores
age1qyqszqgpqyqszqgpqyqszqgpqyqszqgp4d9k7mzv0lr2t8hxq…

Read the full security page: how push-to-Vercel works when we cannot read your values, everything our server can still see if it is breached tomorrow, and the six limitations we have not fixed yet.

Encrypted on deviceNothing is sent in the clear, not even for a second.
No key on our sideWe cannot read your values, and neither can a subpoena.
Revoke in one clickSomeone leaves, they lose access to every project at once.

The vault, for the
secrets that aren't
KEY=value.

A service-account JSON, an Apple .p8, a PEM or SSH deploy key, recovery codes, a connection string, a plain note. Same encryption as your env vars, kept as a separate collection so nothing that touches .env files or Vercel can reach it.

Each entry gets a free-text label, not a shouty variable name, and a kind that only picks an icon. No client is allowed to parse a value because of it.

Vault · orbit-api4 / 100
Apple App Store Connect key (2026)
p8
1.4 KB
Firebase admin (prod)
service_account
2.3 KB
Deploy key for orbit-api
ssh_key
0.4 KB
Recovery codes, root account
note
0.2 KB
Label and kind are plaintext to the relay. The value never is.
Separate by structureA pull cannot write a vault entry into a .env and a Vercel push cannot send one. They iterate the other map, so there is no filter to forget.
Revoked in the same writeRemoving a member re-encrypts the vault alongside the keys, atomically. A client that submits one without the other is refused.
No escrow, no overridePrivate keys live only in the macOS Keychain, never on disk. Delete an entry and you destroy the only encrypted copy.
What it does not hide: the relay can see a project holds “Firebase admin (prod)” of kind service_account. That is the same exposure a name like STRIPE_SECRET_KEY already carries. Re-encrypting on removal also cannot revoke a copy already sitting on someone's laptop.
Creating an entry is Pro. Existing entries stay readable, editable and deletable on Free. A downgrade never takes away what you already have.

A moving truck
for one chair.

Vault, Doppler and Infisical are built for security teams: roles, policies, compliance dashboards. If three people share a Stripe key, none of that helps.

MiniEnv
Vault · Doppler · Infisical
Setup
Download, sign in, share a project
Define projects, roles and scopes before anyone reads a value. Vault, a server too.
Access model
The people you invite
Roles, policies, service accounts, machine identities
Built for
Teams of 3 to 10 sharing real keys
Security and compliance organisations
Five people
Free
Doppler $16/mo · Infisical free, until you add a CI token · Vault self-hosted, plus a server
Ten people
$29.99/mo, flat
Doppler $56–210 · Infisical $200–230 · Vault, ask sales

Prices from each vendor's public pricing page, checked 27 August 2026. Infisical bills "any human or machine that authenticates" as an identity, so CI tokens count as seats.

Or never leave
the terminal.

The CLI does the same encryption on your machine, with the same Keychain identity as the app. No command ever prints a value, at any verbosity.

macOS · Node 20 · coming soon
~/code/orbit-api
$

Free until your
team outgrows it.

One download either way. Pro is unlocked inside the app, whenever you actually need it.

Free
$0
Up to 5 people, including you.
Unlimited projects and variables
End-to-end encryption
Prod and staging tabs
macOS app
Pro
in-app
$29.99/mo
Unlimited people, up to 3 teams.
Separate production, preview and development values
Push and pull straight to Vercel
Activity log, plus alerts for keys nobody has rotated
Import every .env in a folder at once
A vault for the secrets that are not env vars
Download free for
Same app for both plans · Apple Silicon · macOS 12 or later
Questions? Send us a message.
©2026 MiniEnv